Files
new-api/service/authz/permission.go
T
Calcium-Ion 4aee5f7d5a feat: better admin permissions (#5755)
* feat: add casbin admin permissions

* feat: improve audit logging to associate logs with actual operators and target users

* feat: enhance admin permissions and UI interactions for sensitive actions

* Refactor authz RBAC and tighten channel permissions

* Split channel authz field policy

* Address channel authz review findings
2026-06-27 17:01:59 +08:00

28 lines
585 B
Go

package authz
import "strconv"
// Permission identifies a single action on a resource.
type Permission struct {
Resource string
Action string
}
// PermissionsMap is a resource -> action -> allowed lookup.
type PermissionsMap map[string]map[string]bool
const (
EffectAllow = "allow"
EffectDeny = "deny"
)
// UserSubject is the casbin subject string for a single user.
func UserSubject(userID int) string {
return "user:" + strconv.Itoa(userID)
}
// RoleSubject is the casbin subject string for a role.
func RoleSubject(roleKey string) string {
return "role:" + roleKey
}